Skip to main content

Command Palette

Search for a command to run...

Impersonation still needs authorization

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

When an admin or support tool lets someone "act as" another user, that mode is still an authorization decision — not a free pass.

Check all of these before allowing impersonation:

  1. The actor is allowed to impersonate at all.
  2. They may assume this specific target (tenant, role, customer tier).
  3. Which actions are permitted while acting as that user (often a subset of the target's permissions).
  4. Both identities are recorded on every request and in the audit log.

Impersonation without those checks is privilege escalation dressed as a convenience feature. Authenticate the actor, then authorize the impersonation itself, then authorize each action under the assumed identity.